Summaries are AI-assisted and may contain errors — always read the original. We link to every source and never republish full articles.
PrivacySignal Actionable intelligence for privacy, AI governance & digital regulation
● Live
BleepingComputer: Clean GitHub repo tricks AI coding agents into running malware Politico — Tech: Tech industry grapples with Trump’s AI about-faces NPR — Tech: Trump administration partially lifts export ban on Anthropic's most advanced AI model WIRED: I Tried DeleteMe, a Service That Removes Your Personal Info From the Internet The Guardian — Tech: Australian rescue team uses AI-powered drone to find lost hikers – video Information Commissioner's Office: Care 4 All Ltd New York Times — Tech: U.S. Loosens Restrictions on Anthropic’s Mythos A.I. Model WIRED — AI: Trump Administration Allows Anthropic to Release Mythos to Select US Organizations DataBreaches.net: Russian Hackers Behind the $2.5 Billion Jaguar Land Rover Cyberattack, Investigators Say Schneier on Security: Meta Is Testing Facial Recognition for Police and Military CNIL: Emerging technologies and the protection of children: G7 data protection authorities agree on key principles IAPP: The state of enforcement: Part I — Consumer privacy rights The Record: Russia used social engineering to breach prominent messaging accounts, Ukraine says HIPAA Journal: Okanogan Behavioral Healthcare Settles Class Action Data Breach Lawsuit Privacy Commissioner of Canada: News release: Privacy Commissioner of Canada strengthens international cooperation at the 2026 G7 Data Protection and Privacy Authorities Roundtable BBC — Tech: Teens who hacked TfL were known to police years before cyber-attack EDPS: Newsletter Digest - news from the EDPS MIT Technology Review — AI: Repositioning retail for the AI era EDPB: One-Stop-Shop case digest on right to object and right to erasure updated CISA (.gov): Horner Automation Cscape BleepingComputer: Clean GitHub repo tricks AI coding agents into running malware Politico — Tech: Tech industry grapples with Trump’s AI about-faces NPR — Tech: Trump administration partially lifts export ban on Anthropic's most advanced AI model WIRED: I Tried DeleteMe, a Service That Removes Your Personal Info From the Internet The Guardian — Tech: Australian rescue team uses AI-powered drone to find lost hikers – video Information Commissioner's Office: Care 4 All Ltd New York Times — Tech: U.S. Loosens Restrictions on Anthropic’s Mythos A.I. Model WIRED — AI: Trump Administration Allows Anthropic to Release Mythos to Select US Organizations DataBreaches.net: Russian Hackers Behind the $2.5 Billion Jaguar Land Rover Cyberattack, Investigators Say Schneier on Security: Meta Is Testing Facial Recognition for Police and Military CNIL: Emerging technologies and the protection of children: G7 data protection authorities agree on key principles IAPP: The state of enforcement: Part I — Consumer privacy rights The Record: Russia used social engineering to breach prominent messaging accounts, Ukraine says HIPAA Journal: Okanogan Behavioral Healthcare Settles Class Action Data Breach Lawsuit Privacy Commissioner of Canada: News release: Privacy Commissioner of Canada strengthens international cooperation at the 2026 G7 Data Protection and Privacy Authorities Roundtable BBC — Tech: Teens who hacked TfL were known to police years before cyber-attack EDPS: Newsletter Digest - news from the EDPS MIT Technology Review — AI: Repositioning retail for the AI era EDPB: One-Stop-Shop case digest on right to object and right to erasure updated CISA (.gov): Horner Automation Cscape

Top Stories

AI Governance
New York Times — Tech · · International

U.S. Loosens Restrictions on Anthropic’s Mythos A.I. Model

The move de-escalates a clash between the Trump administration and the company over its cutting-edge artificial intelligence systems.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy #ai-governance#ai Read original →
AI Governance
MIT Technology Review — AI · · International

Three things to watch amid Anthropic’s latest feud with the government

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. For those of you enjoying your summer unaware of Anthropic’s latest feud with the US government, here’s a recap: In April the company said it had built an AI model called Mythos…

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →
AI Governance
Politico — Tech · · International

House kids’ safety deal complicates AI talks

Keeping kids safe online has become the linchpin to getting an artificial intelligence bill done in Washington. The House and Senate can’t seem to agree on either.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
A Americans for Responsible Innovation · · International

CREATE AI Act Passes House Committee

CREATE AI Act Passes House Committee  Americans for Responsible Innovation

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Enforcement
The Guardian — Tech · · International

Whistleblower Sarah Wynn-Williams sues Meta over attempts to ‘silence’ her

Former employee files complaint accusing company of ‘coercive surveillance’ and first amendment violation The Meta whistleblower Sarah Wynn-Williams is suing the tech company over its efforts to “silence” her. A 57-page complaint filed to a US district court in California on Thursday argues that an interim arbitration ruling sought by Meta preventing Wynn-Williams from publicising her memoir, Careless People, was “improper and unlawful” and a “blatant violation of the first amendment”. It also accuses the company of “coercive surveillance”. Continue reading...

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
AI Governance
New York Times — Tech · · International

How a Niche Technology Became a Choke Point for A.I.

Advanced chip packaging, which boosts computing power for artificial intelligence, has made the United States more reliant on Taiwan than ever.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Healthcare
HIPAA Journal · · US Federal

Healthcare Report Highlights Growing Vendor Risk and Lack of Cyberattack Readiness

Cybersecurity risk is growing, and healthcare organizations are struggling to defend a rapidly increasing attack surface. AI tools are being […] The post Healthcare Report Highlights Growing Vendor Risk and Lack of Cyberattack Readiness appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai Read original →
Breach
HIPAA Journal · · US Federal

Okanogan Behavioral Healthcare Settles Class Action Data Breach Lawsuit

Okanogan Behavioral Healthcare, a Washington-based behavioral health services provider, has reached a settlement in a class action lawsuit stemming from a data breach affecting its patients. The resolution signals continued legal and financial exposure for smaller regional healthcare entities handling sensitive mental and behavioral health records.

Why this matters: Healthcare privacy officers and legal teams should note that behavioral health providers—often under-resourced—face significant class action liability following breaches, reinforcing the urgency of robust HIPAA-compliant security controls.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →

Analysis · our original take

All analysis →

AI & Society

News
BleepingComputer · · International

Clean GitHub repo tricks AI coding agents into running malware

An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]

Who should care: General readers · AI governance · Policy

#ai#security Read original →
News
Politico — Tech · · International

Tech industry grapples with Trump’s AI about-faces

Silicon Valley billionaires backed Trump due to fears that Democrats would overregulate AI. Now the White House is restricting the release of new AI models — and tech lobbyists are cautiously searching for answers.

Who should care: General readers · AI governance · Policy

News
T The Virginian-Pilot · · International

Cartoon: AI Regulation

Cartoon: AI Regulation  The Virginian-Pilot

Who should care: Lawyers · Compliance · General readers · AI governance · Policy

#regulation#ai Read original →
News
The Guardian — Tech · · International

OpenAI staggers AI model release after Trump administration request

Sam Altman announces limited preview of GPT 5.6 in move that echoes launch of Anthropic’s Mythos Business live – latest updates OpenAI is staggering the release of its latest AI model after a request from the US government, in a move echoing the launch of Anthropic’s Mythos product. The company behind ChatGPT signalled its dissatisfaction with the move, saying that doing so keeps the best AI tools from “users, developers, enterprises, cyber defenders, and global partners who need them”. Continue reading...

Who should care: General readers · AI governance · Policy

News
Schneier on Security · · International

AI and Liability

Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information generated with AI should not be blindly trusted,” the court held that the AI’s summaries are reflections of the company and “above all an expression of Google’s business activities.” This is the latest skirmish in a decades-old battle over internet publishing. Historically, there were two different types of information distributors: carriers and publis…

Who should care: General readers · AI governance · Policy

Healthcare
EDPS · · EU

Newsletter Digest - news from the EDPS

The European Data Protection Supervisor has released a newsletter covering four priority areas shaping EU digital governance: the Digital Omnibus legislative debate, cross-border health data protection, AI safeguards for the EU Visa Application Platform chatbot, and transparency obligations around EU fund usage.

Why this matters: Privacy officers, healthcare teams, and AI-governance professionals should monitor these EDPS developments closely, as they signal upcoming regulatory expectations across health data flows, public-sector AI deployment, and digital policy reform.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · AI governance · General readers · Policy

#healthcare#gdpr#ai Read original →

AI Governance

AI Governance
OECD AI Policy Observatory · · International

Designing transparency for government AI: Insights from the UK’s Algorithmic Transparency Recording Standard initiative

How the UK’s ATRS strengthens algorithmic transparency, public trust and accountability in government AI. The post Designing transparency for government AI: Insights from the UK’s Algorithmic Transparency Recording Standard initiative appeared first on OECD.AI.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →
AI Governance
The Guardian — Privacy · · International

Dynamic pay on platforms such as Uber should be banned, says TUC

Exclusive: Union body finds workers describing themselves as ‘gambling’ because wages felt like the outcome of chance rather than work The practice of using “dynamic pricing” to set pay on gig economy platforms including Uber should be banned because it leaves workers at the mercy of shadowy algorithms with no certainty over their earnings, trade union leaders have urged. In a report exposing the human cost of the gig economy practice, the Trades Union Congress said pay was becoming decoupled from time, skill or effort. Instead, work had become a speculative practice with the rewards determin…

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →
AI Governance
MIT Technology Review — AI · · International

Three things to watch amid Anthropic’s latest feud with the government

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. For those of you enjoying your summer unaware of Anthropic’s latest feud with the US government, here’s a recap: In April the company said it had built an AI model called Mythos…

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →
AI Governance
Politico — Tech · · International

House kids’ safety deal complicates AI talks

Keeping kids safe online has become the linchpin to getting an artificial intelligence bill done in Washington. The House and Senate can’t seem to agree on either.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
New York Times — Tech · · International

U.S. Loosens Restrictions on Anthropic’s Mythos A.I. Model

The move de-escalates a clash between the Trump administration and the company over its cutting-edge artificial intelligence systems.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
OECD AI Policy Observatory · · International

The OECD AI Policy Toolkit: Better AI policies for better lives

OECD AI Policy Toolkit helps governments turn AI principles into action with practical guidance, policy examples and global insights. The post The OECD AI Policy Toolkit: Better AI policies for better lives appeared first on OECD.AI.

Who should care: AI governance · Lawyers · Administrators · Compliance · General readers · Policy

#ai-governance#regulation#ai Read original →
AI Governance
The Guardian — Tech · · International

‘You can’t make billions without hurting people’: Cory Doctorow on Elon Musk, the AI bubble and bosses’ cruel fantasies

The writer who coined the word ‘enshittification’ tells us why AI will never deliver what it promises – and why it still appeals so much to those in power A “centaur”, in automation theory, is a person assisted by a machine, and a “reverse centaur”, hero of Cory Doctorow’s new book, The Reverse Centaur’s Guide to Life After AI, is a “human who is conscripted into acting as an assistant to a machine”. Every warehouse worker who ever had to urinate in a water bottle because they couldn’t otherwise meet the fulfilment targets set by an algorithm is a reverse centaur. Reaching into the future, ev…

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →
AI Governance
MIT Technology Review — AI · · International

Why do South Koreans love AI so much?

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. When I landed in Seoul after a grueling 12-hour flight from San Francisco, I walked through an unmanned immigration checkpoint, where a machine scanned my face and passport. On the subway home,…

Who should care: AI governance · Lawyers · Administrators · General readers · Policy · Privacy officers

#ai-governance#ai#privacy Read original →

Healthcare Privacy

Healthcare
EDPS · · EU

Newsletter Digest - news from the EDPS

The European Data Protection Supervisor has released a newsletter covering four priority areas shaping EU digital governance: the Digital Omnibus legislative debate, cross-border health data protection, AI safeguards for the EU Visa Application Platform chatbot, and transparency obligations around EU fund usage.

Why this matters: Privacy officers, healthcare teams, and AI-governance professionals should monitor these EDPS developments closely, as they signal upcoming regulatory expectations across health data flows, public-sector AI deployment, and digital policy reform.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · AI governance · General readers · Policy

#healthcare#gdpr#ai Read original →
Healthcare
A Atlantic Council · · International

Balancing openness and control: Cross-border health data and AI governance in China

The Atlantic Council has examined how China navigates the tension between enabling international data flows and maintaining strict regulatory control over health data and AI systems, highlighting the country's dual approach to fostering innovation while asserting sovereignty over sensitive information.

Why this matters: Professionals operating in or partnering with Chinese entities must understand this regulatory duality, as it directly affects cross-border data transfer compliance, AI deployment agreements, and health data governance strategies.

Who should care: Healthcare professionals · Privacy officers · Compliance · AI governance · Lawyers · Administrators · General readers · Policy

#healthcare#ai-governance#ai Read original →
Healthcare
The Guardian — Privacy · · International

Palantir’s access to identifiable NHS England patient data is ‘dangerous’, MPs say

Health service has given US tech firm ‘unlimited access’ to certain data to build integrated platform, according to reports UK politics live – latest updates MPs have warned that an NHS decision to grant Palantir access to identifiable patient information in its plan to use AI to improve the health service is “dangerous” and will fuel public fears that data privacy is not being prioritised. NHS England has allowed staff from the US tech firm and other contractors to access patient data before it has been pseudonymised, despite internal fears of a “risk of loss of public confidence”, the Finan…

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai Read original →
Healthcare
HIPAA Journal · · US Federal

Healthcare Report Highlights Growing Vendor Risk and Lack of Cyberattack Readiness

Cybersecurity risk is growing, and healthcare organizations are struggling to defend a rapidly increasing attack surface. AI tools are being […] The post Healthcare Report Highlights Growing Vendor Risk and Lack of Cyberattack Readiness appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai Read original →
Healthcare
DataBreaches.net · · International

UK: Boy’s medical records may have been accessed inappropriately after crocodile attack at zoo

They could have — and should have — anticipated great curiosity about this particular patient’s medical records. Did they control access well enough? Emily Stevens reports: The medical records of a young boy who was attacked by a crocodile at a Cambridgeshire zoo were accessed by up to 40 members of staff. The incident took... Source

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
The Guardian — Privacy · · International

Shared NHS patient records could cut 20,000 A&E visits a year, ministers claim

Modernisation bill would require GPs and hospitals in England to share data, reducing errors and duplication Sharing access to patients’ health data across NHS providers in England could result in 20,000 fewer A&E visits a year and save £20m annually, the government has claimed, before the second reading of the NHS modernisation bill on Monday. The bill, which would also abolish NHS England, sets out measures including single patient records (SPR) for every person receiving health and social care in England, requiring GPs and hospitals to securely share data as part of the government’s 10…

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Why You Don’t Need to Understand HIPAA to Make Your Small Practice HIPAA Compliant

A small practice owner who cannot define a Security Risk Analysis, has never read the HIPAA Security Rule, and does […] The post Why You Don’t Need to Understand HIPAA to Make Your Small Practice HIPAA Compliant appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
The Guardian — Privacy · · International

What is the UK Biobank project and what are the privacy concerns around it?

Volunteers’ data has enabled medical breakthroughs, but there are questions over how that data is protected With the revelation that the confidential health records of half a million British volunteers have been put up for sale on a Chinese website, we take a look at what the UK Biobank project has achieved – and why concerns have been raised. Continue reading...

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

HIPAA Security Rule Training for Business Associates

HIPAA Business Associates that create, receive, maintain, or transmit electronic Protected Health Information on behalf of HIPAA-covered entities are directly […] The post HIPAA Security Rule Training for Business Associates appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

Colorado Health Network; Kentucky Mountain Health Alliance Announce Data Breaches

Data security incidents have been announced by the Colorado Health Network and Kentucky Mountain Health Alliance. In both cases, only […] The post Colorado Health Network; Kentucky Mountain Health Alliance Announce Data Breaches appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →

GDPR / International

GDPR / Intl
EDPS · · EU

Hired by an algorithm: Data protection and AI regulation in modern HR practices

A forthcoming conference co-organized with EDPB trainees, scheduled for 9 July, will examine the growing use of artificial intelligence in hiring and recruitment workflows and the data protection challenges these practices create under current regulatory frameworks.

Why this matters: HR, legal, and privacy teams should monitor developments from this event, as EDPB involvement signals potential guidance or enforcement priorities around AI-driven recruitment tools.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · Compliance · General readers · Policy

#gdpr#ai-governance#regulation#ai#privacy Read original →
GDPR / Intl
IAPP · · International

A view from Brussels: A sneak peek into upcoming guidelines on GDPR, AI Act interplay

European regulators are preparing guidance that will clarify how the GDPR and the EU AI Act interact, offering organizations a clearer compliance framework where both regimes overlap. The forthcoming guidelines signal that data protection and AI governance obligations will need to be addressed in an integrated, rather than siloed, manner.

Why this matters: Privacy officers and AI governance teams should anticipate and begin reconciling dual compliance obligations before official guidelines release, as misalignment between GDPR and AI Act requirements could expose organizations to compounded regulatory risk.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
GDPR / Intl
OECD AI Policy Observatory · · International

Rethinking AI data: From scraping to sustainable and ethical data sharing

An OECD.AI initiative called VIADUCT is examining how the AI industry can move beyond indiscriminate web scraping toward structured, consent-based data-sharing frameworks that address copyright obligations, GDPR compliance, and equitable access to training datasets.

Why this matters: Privacy officers, legal counsel, and AI governance teams should monitor VIADUCT's emerging frameworks, as they may shape regulatory expectations and contractual standards for lawful AI training data procurement.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
GDPR / Intl
EDPB · · EU

EDPB gets a new look: discover the new website and brand identity

Brussels, 22 June - Since its establishment in 2018, the core mission of the EDPB has been to uphold and safeguard the right to data protection. Over the years, the EDPB has played a key role in ensuring the consistent application of the GDPR across Europe, by providing guidance on key GDPR concepts and the interaction of the GDPR with other digital laws, as well as through the adoption of consistency opinions and binding decisions. The EDPB is also committed to making GDPR compliance easier for organisations and enhancing its dialogue with stakeholders. The EDPB is glad to announce today the…

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
GDPR / Intl
DataBreaches.net · · International

UK: ICO statement on ‘Edtech examined’ report

The UK Information Commissioner’s Office (ICO) has released a report titled “EdTech examined — Key Findings from Our Audits.” The ICO issued the following statement to accompany the report’s release: Today, the ICO has published ‘Edtech examined’, a new report which outlines how we have worked directly with edtech providers to review and improve data protection practices... Source

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
EDPS · · EU

Latest EDPS Newsletter out now

Latest EDPS Newsletter out now ileanjoh Tue, 06/16/2026 - 17:08 Wed, 06/17/2026 - 12:00 Welcome to the latest edition of the EDPS Newsletter, featuring active AI governance and major supervisory milestones. Catch up on our Annual Report 2025, recommendations for the EU visa platform chatbot, insights from the Digital Omnibus high-level debate, and a preview of our upcoming trainees' conference on AI in hiring practices! 1 Read more here

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
GDPR / Intl
EDPB · · EU

One-Stop-Shop case digest on right to object and right to erasure updated

Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs). Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's public register by selecting and presenting the most important decisions on a given theme and providin…

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →

Enforcement & Fines Tracker

Figures auto-extracted from headlines & excerpts — verify against the original source.

Data Breaches

Breach
HIPAA Journal · · US Federal

Okanogan Behavioral Healthcare Settles Class Action Data Breach Lawsuit

Okanogan Behavioral Healthcare, a Washington-based behavioral health services provider, has reached a settlement in a class action lawsuit stemming from a data breach affecting its patients. The resolution signals continued legal and financial exposure for smaller regional healthcare entities handling sensitive mental and behavioral health records.

Why this matters: Healthcare privacy officers and legal teams should note that behavioral health providers—often under-resourced—face significant class action liability following breaches, reinforcing the urgency of robust HIPAA-compliant security controls.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
T TicketNews · · International

MSG Data Breach Lawsuit Puts Dolan’s Facial Recognition/Data Fight in Spotlight

A lawsuit targeting Madison Square Garden over a data breach has drawn renewed attention to owner James Dolan's controversial use of facial recognition technology at MSG venues, raising questions about how biometric data is collected, stored, and protected in live entertainment settings.

Why this matters: Privacy officers and legal teams should monitor this case closely, as it may establish precedent on biometric data liability and breach notification obligations for venues deploying facial recognition systems.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#surveillance#privacy Read original →
Breach
TechCrunch — Privacy · · International

Italian prosecutors confirm journalist was hacked with Paragon spyware

Italian prosecutors have confirmed that two journalists were targeted using Paragon spyware, advancing a broader national investigation into the tool's deployment. The identity of the party or parties who authorized the surveillance remains officially unresolved.

Why this matters: This case signals growing regulatory and prosecutorial scrutiny of commercial spyware vendors, with direct implications for organizations advising on lawful surveillance boundaries, press freedom protections, and device security posture.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#surveillance Read original →
Breach
EDPB · · EU

EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

Brussels, 10 June – During its latest plenary, the EDPB met with Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection. In addition, the Board has adopted a common data breach notification template. The Board held a meeting with Commissioner McGrath, engaging in a fruitful discussion about common priorities and ongoing work on areas of mutual interest. The Digital Omnibus was among the key topics that shaped the discussion. The Board reiterated that, while several proposed changes have been welcomed by the Board, it is crucial not to adopt the proposed…

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance · Compliance

#breach#gdpr#regulation Read original →
Breach
The Guardian — Privacy · · International

UK Biobank has my data, but I’m not worried. I know the benefits are too great to consider pulling out | Polly Toynbee

Longitudinal studies are a research jewel, shedding light on motor neurone disease, cot deaths, Alzheimer’s and more. Don’t let the security breach in China put you off joining one One thing Britain is exceptionally good at is collecting and using health data for research, studying cohorts of people over many decades. A shudder of alarm rippled through the research world at the news this week that UK Biobank’s data had been put up for sale on China’s Alibaba site, with the science minister, Patrick Vallance, saying that more attempts to sell the data in China were expected. Some sensationalis…

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
FTC Consumer Protection · · US Federal

FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students’ Personal Data

Following a public comment period, the Federal Trade Commission finalized a modified order requiring Illuminate Education Inc. to implement a data security program, limit collection and retention of consumer data, and delete unnecessary data to settle charges that the company’s data security failures led to a major data breach involving the personal data of millions of students. In its complaint, the FTC alleged that Wisconsin-based Illuminate claimed to protect the privacy and security of the student data it maintained but failed to deploy reasonable security measures to prote…

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
EDPS · · EU

Managing Shadow AI’s Hidden Data Breach Risk

Managing Shadow AI’s Hidden Data Breach Risk francesco Mon, 06/15/2026 - 09:25 Mon, 06/15/2026 - 12:00 The use of unauthorised AI tools that can expose personal data, create regulatory blind spots, and open security vulnerabilities. 1 Read blogpost by Wojciech Wiewiórowski

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · AI governance · Policy

#breach#regulation#ai#security Read original →

Data Breach Tracker

Figures auto-extracted from headlines & excerpts — verify against the original source.

Enforcement Actions

Enforcement
The Guardian — Privacy · · International

UK information commissioner steps back amid workplace investigation

UK Information Commissioner John Edwards has temporarily recused himself from his role while the ICO conducts an independent inquiry into undisclosed internal HR matters. Edwards confirmed his cooperation with the investigation via a LinkedIn statement, leaving the data protection regulator without its principal figurehead during the probe.

Why this matters: Leadership instability at the ICO could affect the pace and consistency of regulatory decisions, enforcement actions, and guidance relevant to privacy, AI governance, and data protection compliance across sectors.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#regulation#privacy Read original →
Enforcement
N News4JAX · · International

Fort Myers man sues Jax Beach police, JSO after AI facial recognition leads to wrongful arrest, lawsuit says

A Fort Myers man has filed a lawsuit against Jacksonville Beach police and the Jacksonville Sheriff's Office, alleging that AI-powered facial recognition technology misidentified him and resulted in a wrongful arrest. The case highlights ongoing concerns about the reliability and civil rights implications of law enforcement's use of automated identification systems.

Why this matters: This litigation signals growing legal exposure for agencies deploying facial recognition, reinforcing the need for legal and governance teams to audit AI tool accuracy, bias risks, and civil liability frameworks before deployment.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · AI governance · Policy

#enforcement#surveillance#ai#privacy Read original →
Enforcement
Privacy Commissioner of Canada · · Canada

News release: Privacy Commissioner of Canada investigation into the Grok chatbot and sexualized deepfakes finds companies violated privacy law

Canada's Privacy Commissioner concluded an investigation finding that the companies behind the Grok chatbot violated Canadian privacy law in connection with the generation of sexualized deepfake content, marking a significant regulatory enforcement action in the AI-generated imagery space.

Why this matters: Privacy and AI-governance teams should note this signals active regulatory scrutiny of generative AI platforms under existing privacy frameworks, with potential liability implications for companies deploying similar tools.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai#privacy Read original →
Enforcement
EDPB · · EU

Supporting GDPR consistency: EDPB launches dedicated form

Brussels, 24 June – The EDPB has launched a dedicated contact form for stakeholders to report possible inconsistencies in how the GDPR is interpreted across Europe. This initiative reflects the commitments set out in the EDPB Helsinki Statement on enhanced clarity, support and engagement, aimed at strengthening the dialogue with stakeholders and ensuring consistent GDPR enforcement across Europe. The new tool enables stakeholders to report alleged divergences between national positions, as well as between national positions and those of the EDPB. The EDPB will not respond to individual submis…

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
Data Protection Commission · · EU / Ireland

Fines

Fines  Data Protection Commission

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
FTC Consumer Protection · · US Federal

FTC Begins Enforcing the TAKE IT DOWN Act

The Federal Trade Commission today began enforcing the TAKE IT DOWN Act (TIDA), a law requiring platforms, at the request of victims, to remove intimate photos or videos shared online without victims’ consent. As part of its enforcement role, the FTC has launched TakeItDown.ftc.gov, a website allowing victims and survivors to submit complaints about platforms that have failed to act on valid requests for the removal of nonconsensual intimate images. The website also accepts complaints about platforms that have failed to create a process for people to request removal of these images. “Thanks t…

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
The Guardian — Tech · · International

Whistleblower Sarah Wynn-Williams sues Meta over attempts to ‘silence’ her

Former employee files complaint accusing company of ‘coercive surveillance’ and first amendment violation The Meta whistleblower Sarah Wynn-Williams is suing the tech company over its efforts to “silence” her. A 57-page complaint filed to a US district court in California on Thursday argues that an interim arbitration ruling sought by Meta preventing Wynn-Williams from publicising her memoir, Careless People, was “improper and unlawful” and a “blatant violation of the first amendment”. It also accuses the company of “coercive surveillance”. Continue reading...

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →

Under the Radar

Healthcare
EDPS · · EU

Newsletter Digest - news from the EDPS

The European Data Protection Supervisor has released a newsletter covering four priority areas shaping EU digital governance: the Digital Omnibus legislative debate, cross-border health data protection, AI safeguards for the EU Visa Application Platform chatbot, and transparency obligations around EU fund usage.

Why this matters: Privacy officers, healthcare teams, and AI-governance professionals should monitor these EDPS developments closely, as they signal upcoming regulatory expectations across health data flows, public-sector AI deployment, and digital policy reform.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · AI governance · General readers · Policy

#healthcare#gdpr#ai Read original →
GDPR / Intl
EDPB · · EU

One-Stop-Shop case digest on right to object and right to erasure updated

Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs). Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's public register by selecting and presenting the most important decisions on a given theme and providin…

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
AI Governance
OECD AI Policy Observatory · · International

AI for inclusive and resilient agri-food systems: Potential ways forward

AI can strengthen food security, resilience and sustainability in agriculture. Explore key challenges and opportunities for agri-food systems. The post AI for inclusive and resilient agri-food systems: Potential ways forward appeared first on OECD.AI.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
GDPR / Intl
EDPS · · EU

Espresso with the EDPS: AI Literacy

Espresso with the EDPS: AI Literacy miriam Tue, 06/23/2026 - 13:31 Tue, 06/23/2026 - 12:00 What does it mean to be AI literate? And why does it matter for all of us? The first episode of our new video series "Espresso with the EDPS" by Secretary General, is now live! 1 Watch it

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy